<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:35:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-379756</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-379756</link>
      <description>EUVD-2026-379756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-379756</guid>
    </item>
    <item>
      <title>fkie_cve-2026-102828</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-102828</link>
      <description>&lt;p&gt;simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.&amp;lt;token&amp;gt;.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.&amp;lt;token&amp;gt;.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-102828</guid>
    </item>
    <item>
      <title>GHSA-x6jw-m9v5-85vh — simple-git unsafe-operation guard does not block trailer command configuration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x6jw-m9v5-85vh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: simple-git&lt;/p&gt;
&lt;p&gt;## Affected product&lt;/p&gt;
&lt;p&gt;The default `blockUnsafeOperationsPlugin` in `simple-git` when an application permits untrusted values to reach `SimpleGitOptions.config` or Git inline configuration arguments such as `-c &amp;lt;key&amp;gt;=&amp;lt;value&amp;gt;`.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`trailer.&amp;lt;token&amp;gt;.cmd` is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a `GitPluginError`.&lt;/p&gt;
&lt;p&gt;Git documents `trailer.&amp;lt;token&amp;gt;.cmd` as a shell command invoked by `git interpret-trailers`. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.&lt;/p&gt;
&lt;p&gt;## Technical details&lt;/p&gt;
&lt;p&gt;`simple-git/src/lib/git-factory.ts` installs `commandConfigPrefixingPlugin` before `blockUnsafeOperationsPlugin`. The prefixing plugin in `simple-git/src/lib/plugins/command-config-prefixing-plugin.ts` turns every `SimpleGitOptions.config` entry into `-c &amp;lt;key&amp;gt;=&amp;lt;value&amp;gt;` before the unsafe-operation plugin evaluates the final argv.&lt;/p&gt;
&lt;p&gt;In `simple-git@3.36.0`, `blockUnsafeOperationsPlugin` delegates to `@simple-git/argv-parser`. `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` compares parsed configuration writes against `preventUnsafeConfig`. That list has no matcher for `trailer.&amp;lt;token&amp;gt;.cmd`, so the invocation is allowed.&lt;/p&gt;
&lt;p&gt;Git v2.39.5&amp;#39;s `Documentation/git-interpret-trailers.txt` states that `trailer.&amp;lt;token&amp;gt;.cmd` specifies a shell command called to generate or modify a trailer.&lt;/p&gt;
&lt;p&gt;## P…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: simple-git&lt;/p&gt;
&lt;p&gt;## Affected product&lt;/p&gt;
&lt;p&gt;The default `blockUnsafeOperationsPlugin` in `simple-git` when an application permits untrusted values to reach `SimpleGitOptions.config` or Git inline configuration arguments such as `-c &amp;lt;key&amp;gt;=&amp;lt;value&amp;gt;`.&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`trailer.&amp;lt;token&amp;gt;.cmd` is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a `GitPluginError`.&lt;/p&gt;
&lt;p&gt;Git documents `trailer.&amp;lt;token&amp;gt;.cmd` as a shell command invoked by `git interpret-trailers`. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.&lt;/p&gt;
&lt;p&gt;## Technical details&lt;/p&gt;
&lt;p&gt;`simple-git/src/lib/git-factory.ts` installs `commandConfigPrefixingPlugin` before `blockUnsafeOperationsPlugin`. The prefixing plugin in `simple-git/src/lib/plugins/command-config-prefixing-plugin.ts` turns every `SimpleGitOptions.config` entry into `-c &amp;lt;key&amp;gt;=&amp;lt;value&amp;gt;` before the unsafe-operation plugin evaluates the final argv.&lt;/p&gt;
&lt;p&gt;In `simple-git@3.36.0`, `blockUnsafeOperationsPlugin` delegates to `@simple-git/argv-parser`. `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` compares parsed configuration writes against `preventUnsafeConfig`. That list has no matcher for `trailer.&amp;lt;token&amp;gt;.cmd`, so the invocation is allowed.&lt;/p&gt;
&lt;p&gt;Git v2.39.5&amp;#39;s `Documentation/git-interpret-trailers.txt` states that `trailer.&amp;lt;token&amp;gt;.cmd` specifies a shell command called to generate or modify a trailer.&lt;/p&gt;
&lt;p&gt;## P…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x6jw-m9v5-85vh</guid>
    </item>
  </channel>
</rss>
